Research Methodologies for Cybersecurity in Enterprise Environments: A Narrative Review, Synthesis and Executable Guide

2026-08-25Cryptography and Security

Cryptography and Security
AI summary

The authors studied many cybersecurity research methods and found that researchers often need to choose from a variety of approaches before tackling technical problems. They reviewed 151 studies to group methods into eleven categories, explaining what questions each method answers and common mistakes. They created clear, step-by-step guides for each method to help researchers design and report their studies. They also noticed that differences in how studies are designed can explain conflicting results better than differences in the technology being tested. They suggest researchers should carefully match their methods to their research questions and be clear about when their results apply.

systematic reviewdesign-science artifactcontrolled experimentinterview studyattack-graph modelmethodological pluralismevaluation designvalidity threatsintrusion-detection algorithmsreporting checklist
Authors
Tran Duc Le
Abstract
Enterprise cybersecurity research draws on a wider range of methods than any single community routinely teaches. Researchers face a selection problem before they face a technical one: a study may simultaneously need a systematic review, a design-science artifact, a controlled detection experiment, an interview study, or an attack-graph model. This paper addresses that problem in two ways. First, it provides a narrative review and synthesis of methodological practices across a verified corpus of 151 works. We organise these practices into eleven methodology families, detailing for each what questions it answers, the strength of its supporting evidence, and its common failure modes. Second, we convert each family into an executable protocol comprising ordered steps, required instruments, evaluation criteria, common validity threats, and a reporting checklist. Every protocol is also visually mapped to make the sequence, decisions, and threats legible at a glance. We also treat contradictions in the literature as evidence. For example, reported rankings of intrusion-detection algorithms are wildly inconsistent across individually careful studies. We argue this pattern is most parsimoniously explained by variations in evaluation design rather than the algorithms themselves, as these studies differ in design dimensions known to shift results by more than the margins separating the algorithms. Ultimately, the evidence supports methodological pluralism disciplined by explicit validity reasoning. We conclude that researchers must match their evaluation design to the decision under study, triangulate technical against organisational evidence, explicitly state the population a result generalises to, and report the conditions under which the result would not hold.